I went from fintech management to an analyst role at 32 and havent regretted it a day. And it only took me a couple years to get back to a management role.
Safety and security go hand in hand. Its the security teams job to consider safety first and foremost. And there are a lot of parallels with what O’Neil did which we can apply to security.
Similar to Paul O’Neil transformed Alcoa as their CEO. He focused on one thing: Safety. And completely transformed the culture. By reporting, tracking, and remediating all safety incidents he led the company to bounds of operational efficiencies and innovations.
Of course you have your SOC managing events and incidents which should also be reported and follow the same post mortems. Impactful incidents should be prioritized, tracked, and reported to management.
Really drill down the WHY as to how there was an impact to CIA. Find your common and impactful post mortems. You should ask WHY at least 3 times to get to a proper post mortem.
What will this do? This will give your security team enormous amounts of operational data on mishaps and inefficiencies with the business. With proper business impact analysis and system inventory (which many security teams custodian) track these and perform post mortems
@lawrencekingyo Can apply the 80/20 rule to this as well. Really only 20% of the stuff you're working on or concerned with today matters, the other 80% is just filler.
@thedankoe Finally got up at 4:30 today to get my workout in and get all my work done before the kids were up. Now I have a full day with the kids, don't need to try and fit everything in in between!